SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-59293

MEDIUM · CVSS 6.6 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The jCIFS client in affected versions of Spring Integration defaults to negotiating SMB1/CIFS unless explicitly configured to use a higher minimum SMB version, exposing the application to risks such as NTLM relay attacks and content tampering through man-in-the-middle (MITM) vulnerabilities. Organizations using these versions should prioritize updating their configurations to enforce a minimum SMB version to mitigate these security risks. This vulnerability is particularly relevant for those managing file sharing and network communication within their Spring Integration environments.

CVE
CVE-2026-59293
Severity
MEDIUM
CVSS
6.6
EPSS
0.22%

Original NVD Description

Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory signing/encryption and is vulnerable to NTLM relay and content-tampering MITM. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12

Related CVEs

Other vulnerabilities affecting the same vendor(s)